Most open critical and high flaws are over 90 days old
Detectify analyzed exposure data from 1,293 of its customers in the US, the UK and the Nordics and found that most serious flaws still open on their internet-facing systems …
Most organizations need six months or longer to roll out new security controls
Cisco surveyed 8,000 security professionals in 30 markets about how well their organizations defend against AI-era threats, and only 8% landed in the top group. Cisco gave the …
Deepfakes become a board priority once an executive falls for one
Nearly three-quarters of security leaders have encountered or suspect a deepfake attack in the past year, while just 10% say their organizations have purpose-built defenses, …
Cybersecurity hiring practices leave little room for junior talent
Twenty-minute training sessions that fit into the workweek could help new hires become productive sooner, keep employees’ skills current and build problem-solving skills they …
Threat detection dashboards are masking security coverage gaps
A detection rule can show up as deployed on a coverage dashboard and still never fire when an attacker uses the technique it was built to catch. Conifers assessed 14,652 …
Half of threat hunters say bad data is their biggest problem
Half of security professionals name data quality or quantity as their biggest barrier to effective threat hunting, according to the SANS 2026 Threat Hunting Survey. Teams with …
Your incident count is missing a few incidents
If you run security for a brand with hundreds or thousands of locations, the tools you’ve bought may have little to do with whether an attack stays at one store. A new …
Your security program knows about the firewall, but does it know about the elevator?
By early August, attackers had hit water systems in at least seven U.S. states. The FBI and EPA said the intruders remotely accessed internet-facing programmable logic …
Nearly two-thirds of tested websites fail every bot test
Malicious bot activity increased 124% between July 2025 and June 2026, compared with 13.2% growth in human traffic. Traffic from AI agents and large language model crawlers …
The latest deepfake numbers give CISOs plenty to worry about
AI is letting cybercriminals reach deeper into organizations than a phishing email ever could. 41% of CISOs reported at least one social engineering incident involving a …
The next intellectual property thief may sound like your CEO
Impersonation, phishing and domain-name abuse are the most concerning types of online intellectual property infringement, according to CSC’s The State of Online IP Risk 2026 …
Somewhere in your traffic logs, a bot is doing more than looking
Akamai has watched verified AI crawlers, ChatGPT among them, move from reading web pages to sending high-frequency POST requests. In a 30-day analysis of its global customers, …
Featured news
Resources
Don't miss
- Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)
- AI coding agents leaked 13,000 internal company screenshots to public GitHub repos
- OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised
- OWASP Noir: Open-source static analysis tool
- EU Cyber Resilience Act requirements for containers and Kubernetes